Version 1.0 | Effective 21 September 2026
1. What this register covers
NAFCORP PTY LTD uses infrastructure and specialist services to operate PluginChatBot. This register distinguishes providers that process information on our behalf from payment companies and customer-selected services that may also act for their own purposes. A listed company does not necessarily receive every customer's data or every category of information.
This version is a prepared register, not a completed production-location attestation. Provider use is identified below from the reviewed repository or business information. Contracting entities, account-specific locations, retention settings and active tracking services must be confirmed before this register is approved for publication. A provider's general global footprint is not a statement that a particular customer's data is sent to every country in that footprint.
2. Core service providers
Cloudflare - infrastructure and security
Function: hosting the marketing and application Workers and static assets, routing and protecting requests, and operating the D1 database and relevant KV storage. These services are evidenced in the repository architecture and configuration.
Information involved: account and workspace records, conversations and leads stored in the application database, configuration, relevant technical request information, and the limited records necessary for enabled storage functions. The exact information depends on the function being used.
Role: infrastructure provider processing service data on our behalf, with any separate use for its own legal or security purposes governed by applicable terms and law.
Locations and entity: Cloudflare operates an international network. The legal entity on NAFCORP's Cloudflare account, D1 location or jurisdiction configuration, Worker processing, support access and backup arrangements must be recorded from that account. The repository does not establish Australian-only processing. Location hints must not be presented as a binding residency guarantee.
Safeguards to verify: accepted Cloudflare data-processing terms, account access controls, database and backup configuration, deletion capability and any agreed regional restrictions.
OpenAI - AI responses, knowledge resources and supported speech
Function: generating AI answers, processing relevant knowledge content and files, and generating speech when the text-to-speech feature is enabled. Only the information needed for the relevant request or configured knowledge function should be sent.
Information involved: selected messages, instructions and context, uploaded or retrieved knowledge, relevant identifiers and technical usage information; text selected for speech where enabled. A customer must not supply restricted sensitive information through an unapproved workflow.
Role: AI service provider for the functions enabled by PluginChatBot. The contractual OpenAI entity and service terms must be checked against NAFCORP's actual account and any customer-managed credential arrangement.
Locations: OpenAI's standard services and supporting providers involve overseas processing, including the United States. Australian regional storage options, where available, do not prove that NAFCORP has enabled them or that all inference and support occur in Australia. Record the actual project settings and applicable processing countries before publication.
Training and retention: OpenAI states that API data is not used to train its models by default unless the customer opts in. Standard abuse-monitoring retention and endpoint-specific application storage can still apply. Files and knowledge resources may remain until deleted. Confirm data-sharing, storage and retention settings for every active project; a request setting such as store=false is not a general zero-retention guarantee.
SMTP2GO - transactional email
Function: delivery of account verification, password reset, service and other authorised messages. Use of SMTP2GO has been identified by the business and must be reconciled against deployed email configuration.
Information involved: recipient address, necessary sender and message content, and delivery or security records. Do not include full chatbot histories, passwords or unnecessary sensitive records in routine emails.
Role and entity: email-delivery provider. SMTP2GO's published privacy information identifies Sand Dune Mail Ltd, New Zealand. Confirm that this is the relevant contracting entity for the account.
Locations: New Zealand is relevant to the provider's corporate operation. The selected sending and storage infrastructure, support access, subprocessors and retention locations must be verified; a provider's headquarters is not necessarily its sole data-processing location.
3. Payment and account-administration recipients
Stripe
Stripe supplies hosted checkout, payment processing, subscription administration, invoices and the billing portal. It receives information needed for those activities, such as billing contact information, payment details entered into Stripe's interface, transaction information and relevant fraud-prevention data. Ordinary customer chatbot conversations should not be sent to Stripe for payment processing.
Stripe may act both as a service provider and independently for activities such as fraud prevention and legal compliance. It must not be described solely as a processor of visitor conversations. Confirm the relevant Stripe contracting entity, international transfers and product settings from the actual merchant account and accepted terms.
NAFCORP internal signup and support administration
The repository includes a signup synchronisation function that sends account name, email address, telephone number and acceptance status to a configured NAFCORP signup endpoint. NAFCORP itself is the same legal provider, not an additional external subprocessor. Its downstream hosting, CRM, email and support suppliers must nevertheless be included in the underlying data map and this register where appropriate. The final register must state the actual endpoint's purpose and recipients, not merely refer to an unnamed internal system.
Professional advisers or authorities may receive limited information where reasonably necessary and lawful. They are not routine recipients of every chatbot record.
4. Customer-selected integrations
HubSpot: where enabled, relevant lead, contact or conversation information and authorisation credentials are processed to operate the authorised CRM connection. Repository support is evidenced. The customer's own HubSpot relationship, permissions and retention also apply.
Meta services, including WhatsApp, Messenger and Instagram: where connected, channel identifiers, message and contact information and relevant authentication or webhook information pass through the configured channel. These providers may have their own independent purposes and direct terms with the customer or end user. Connection of one channel does not authorise disclosure to every Meta service or to advertising audiences.
GoHighLevel or another CRM/API destination: business information identifies additional integrations, but the exact active implementation, destination and scope must be verified before inclusion as an enabled production recipient. A marketing claim or an integration option alone is not proof that data is currently transferred.
For each enabled integration, record the legal provider, purposes, fields transferred, actual recipient countries where practicable, applicable contract, customer permissions, retention and disconnection/deletion process. Do not enable a new transfer while this assessment remains unresolved. Customer-controlled systems may retain copies under the customer's own obligations after they are disconnected from PluginChatBot.
5. Website analytics and advertising recipients
The website code includes Google consent-mode and data-layer handling. Google Tag Manager is a tag-loading system; the actual container determines which analytics and advertising services run. Google or another tracking service is a recipient only where that service is enabled and receives information. The tag container and browser network behaviour must be inspected before the final provider and cookie inventory is published.
Tracking services must not receive chatbot contents, sensitive information, authentication credentials or unnecessary email addresses from URLs or forms. An analytics or advertising recipient is not a necessary AI-processing subprocessor merely because its tag appears on the marketing site. See the Cookie Policy for the available choices and the distinction between cookies and other transfers.
6. Changes and questions
The notice and objection process in our Data Processing Addendum applies to material changes in subprocessors handling customer data. We will keep a versioned record of approved changes and provide the notice required by that agreement. A new purpose or legally required consent is not satisfied merely by updating a list.
Contact sales@pluginchatbot.com with the subject "Subprocessor enquiry" to request information relevant to a service or raise a concern. We may protect confidential security details and other customers' information while providing an appropriate explanation of the handling affecting you.
7. Approval record required before publication
The person approving this register must confirm: the legal contracting entity for each enabled provider; the enabled product and data categories; the applicable agreement; processing and support countries where practicable; data-sharing and model-training settings; retention and deletion arrangements; any customer-specific restriction; and the date the evidence was checked. Unverified candidates must not be presented as an exhaustive, verified list of live subprocessors. The accompanying implementation report provides the evidence and approval checklist.